NNTP Service STARTTLS Plaintext Command Injection
Medium Nessus Plugin ID 53848
SynopsisThe remote news service allows plaintext command injection while negotiating an encrypted communications channel.
DescriptionThe remote news server contains a software flaw in its STARTTLS implementation that could allow a remote, unauthenticated attacker to inject commands during the plaintext protocol phase that will be executed during the ciphertext protocol phase.
Successful exploitation could allow an attacker access to private newsgroups and reveal a user's credentials.
SolutionContact the vendor to see if an update is available.